Mathias Vermeulen,Laureline Lemoine /Sep 4, 2026Republish
On August 31, the European Commission designated OpenAI’s ChatGPT as a Very Large Online Search Engine (VLOSE), placing the chatbot under the Digital Services Act’s (DSA) most stringent tier of obligations. This decision was long in the making – in fact, we explored different options for how the EC could do this in an extensive paper three years ago.
This designation could have far-reaching implications, both for frontier labs’ products and for the EU’s own rulebook. Many of the questions it raises will only be answered as the Commission’s supervision unfolds over the coming months.
The decision confirms the DSA’s technological neutrality, or at least its ability to bring new kinds of services, ones that didn’t exist when it was drafted, within scope.
One of our arguments for treating ChatGPT as a VLOSE in 2023 rested on Article 3(j) DSA, which defines a search engine as a service that lets users search “in principle, all websites.” At the time, ChatGPT was about to launch a version with web access, giving it exactly that capability. Since then, the search function has been fully integrated into the product, can even be set as a browser’s default one, and both the Commission and OpenAI’s own DSA transparency reports have treated ChatGPT as subject to the general obligations for online search engines since 2024. ChatGPT’s search function will now be subject to the DSA’s due diligence obligations: risk assessments, mitigation measures, independent audits, data access, and transparency reporting.
Still, those 159.1 million search users are only a slice of ChatGPT’s user base in the EU. Impressive as those numbers are, they aren’t how most people actually experience ChatGPT. The chat interface that lets users interact with the model does not necessarily search the web, which makes ChatGPT what the Commission calls a “hybrid service.” The designation decision does not appear to separate out ChatGPT’s different functionalities, which is consistent with how other VLOP designations have worked: Snapchat, for instance, was designated for its social networking component, not its messaging service.
Whether the chat function will ever be designated in its own right, and if so how, remains to be seen. Under Article 34(1), OpenAI must assess risks stemming from the design or functioning of its service and its related systems, and there is a case to be made that the chat function qualifies as such a “related system” in its own right.
But even if that argument doesn’t hold, Article 34 DSA still gives us the opportunity to look under the hood of ChatGPT more broadly. How a general-purpose AI model is designed and used, from training data to output ranking, directly affects the quality, inclusivity, and reliability of the information it puts in front of millions of users. Recital 84 DSA points specifically to algorithmic amplification and curation as a driver of systemic risk, which maps directly onto how ChatGPT selects, ranks, and cites sources. That lens will matter most for risks like negative effects on democratic processes, civic discourse and electoral processes, as well as public security, public health, minors, and mental well-being.
Media pluralism is expressly named as its own systemic risk category, under Article 34(1)(b). The risk assessment should therefore also cover how ChatGPT’s citation and sourcing behavior affects publisher visibility, a question that is not specific to OpenAI. AlgorithmWatch is already using its Article 40(4) vetted-researcher access to investigate whether Google’s AI Overviews are undermining media pluralism by displacing clicks to news sites.
That is another advantage of ChatGPT’s VLOSE designation: it brings OpenAI within the Article 40 data access framework, giving outside researchers the tools to run the same kind of investigation. Vetted researchers can request data under Article 40(4) for research that contributes to detecting and understanding systemic risks under Article 34(1), and to assessing the adequacy of OpenAI’s mitigation measures under Article 35. Article 40(12) goes further, giving non-vetted researchers, including those affiliated with nonprofits, a right to whatever data is publicly accessible on ChatGPT’s interface.
The timing is notable on another front too: the designation lands just weeks after OpenAI announced that advertisers will be able to place ads within ChatGPT across Europe. OpenAI will now have to account for its advertising system in its risk assessment and publish an ad repository under Article 39.
These obligations will only start applying in January 2027, but it’s worth asking what comes next. The DMA does not treat generative AI as a core platform service, but it does regulate online search engines, and now that the Commission has designated ChatGPT as a very large online search engine under the DSA, a gatekeeper designation under the DMA no longer looks far-fetched, provided OpenAI meets the relevant qualitative and quantitative thresholds. That would be a heavier test than the one it has just passed.
Support Tech Policy Press
If you’ve found our work helpful, consider supporting us.
Donate
Authors
Mathias VermeulenMathias Vermeulen is a director at AWO in Brussels, an agency that helps a range of organizations with navigating the complex new policy areas posed by emerging technologies. He is also an affiliated researcher at the Centre for Law, Science, Technology and Society at the Vrije Universiteit Brussel….
Laureline LemoineLaureline Lemoine is a Senior Associate at AWO. Laureline provides legal and policy analysis on a range of issues at the intersection of technology and data rights, including platform regulation (Digital Services Act, Digital Markets Act, Media Freedom Act), online advertising, AI (AI Act, generativ…
